Stadt Leuna
Incident posture
Linked entities
- Victim
- Stadt Leuna
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
The city administration's website suffered a distributed denial‑of‑service attack that rendered it inaccessible for several hours and caused lingering loading problems afterward. The attack targeted the central infrastructure of the service provider brain‑SCC Merseburg GmbH, which hosts the city's data and also serves other municipalities, prompting the provider to deploy dynamic filtering to block suspicious traffic and restore service. The provider confirmed that no data security risk occurred during the incident.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On 29 July 2025 the official website of the city of Leuna, www.leuna.de, became inaccessible starting in the morning and remained unavailable until the late afternoon. The outage was caused by a distributed denial of service (DDoS) attack that flooded the targeted infrastructure with excessive traffic, preventing legitimate users from accessing the site. The attack directed at the central infrastructure components managed by brain‑SCC Merseburg GmbH, the service provider contracted by the city administration to host its online services. Because brain‑SCC also provides hosting for several other municipalities, those entities experienced concurrent disruption.
Throughout the attack the affected web pages endured a sustained increase in server load, which persisted for several hours and resulted in slow or failed page loads even after the initial outage period. On the following day, 30 July 2025, users continued to report difficulties when attempting to load the city’s web pages, indicating lingering effects of the traffic surge. The service provider confirmed that at no point during the incident was there any risk to the confidentiality, integrity, or availability of the underlying data stored on its servers. No data breach or unauthorized access was reported as part of the DDoS event.
In response to the ongoing flood of traffic, brain‑SCC’s technical team implemented targeted countermeasures, including the deployment of dynamic filter mechanisms designed to detect and block suspicious IP addresses associated with the attack. These filters were adjusted in real time as malicious traffic patterns were identified, gradually reducing the volume of illegitimate requests reaching the web servers. By the late afternoon of 29 July 2025 the combined filtering and traffic‑shaping actions had succeeded in mitigating the DDoS pressure, restoring normal accessibility to the city’s website. The city administration subsequently issued an apology for the inconvenience caused by the temporary loss of online services.
Sources
Sources available to members: 1 source.